Back to skill

Security audit

漫剧编剧分镜

Security checks for vulnerabilities and agentic risk

Overview

This skill is a writing aid for Chinese vertical comic storyboard scripts and does not request system access, credentials, persistence, or external data handling.

Safe to install for storyboard/scriptwriting workflows. Be aware that generic trigger terms may activate it when discussing screenwriting, so invoke a different skill explicitly if you do not want this storyboard format.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad, common phrases such as '编剧' and '帮我出分镜', which can cause the skill to activate in contexts where the user did not explicitly intend to invoke this agent. In a workflow that auto-loads skills based on keyword matching, this increases the risk of unintended routing, prompt hijacking via incidental mentions, or inappropriate override of a more suitable skill.

Static analysis

No suspicious patterns detected.